Ransomware Gangs Exploiting WatchGuard Firebox CVSS 9.8 Flaw
CISA confirmed ransomware groups now exploit CVE-2025-14733 in WatchGuard Firebox. Patches shipped December 2025; about 9,000 appliances remain exposed.

CISA updated its Known Exploited Vulnerabilities catalog on September 10, 2026 to add a ransomware tag to CVE-2025-14733, a CVSS 9.8 out-of-bounds write in WatchGuard Fireware OS. The original KEV entry dates to December 19, 2025, when WatchGuard disclosed the flaw and CISA set a federal patch deadline of December 26. Nine months later, roughly 9,000 Firebox appliances are still reachable online with vulnerable firmware.
The flaw
CVE-2025-14733 is an out-of-bounds write in the iked process that handles IKEv2 VPN connections. An unauthenticated remote attacker can trigger it through either mobile user VPN sessions using IKEv2 or branch office VPN tunnels configured with a dynamic gateway peer. Successful exploitation results in arbitrary code execution on the appliance. WatchGuard published affected versions and fixed builds in its PSIRT advisory alongside the December 2025 patch release.
9,000 exposed devices
BleepingComputer reported that approximately 9,000 Firebox appliances with unpatched firmware are publicly accessible as of this week. Ransomware operators routinely scan for exposed VPN gateways. A CVSS 9.8 unauthenticated RCE with no user interaction is exactly the kind of entry point they prioritize.
CISA has not named a specific ransomware group, but the KEV update makes the exploitation status unambiguous: this is happening in real attacks, not just theoretical exploitation.
Patch targets
Affected Fireware OS versions:
- 11.x through 11.12.4_Update1
- 12.x through 12.11.5
- 2025.1 through 2025.1.3
The WatchGuard PSIRT advisory lists the fixed builds. If patching cannot happen immediately, pull the appliance off public internet exposure while you schedule the update. A VPN gateway that cannot be patched should not be reachable from the open internet.
Context
This KEV update landed the same week CISA flagged active exploitation of flaws in Cisco Firepower, Citrix NetScaler, and Fortinet FortiOS. See CISA Sept. 12: Patch Cisco, Citrix, Fortinet Today for the full picture on that cluster. For background on how the KEV catalog works and how federal patch timelines apply, see What Is the CISA KEV Catalog?.
- [ CRITICAL ]CVE-2025-14733WatchGuard Firebox Out of Bounds Write Vulnerability
Found this useful? Share it.


